Control Mapping Readerplace a control, see the map

NIST800-AC-14 AC-14 Permitted Actions Without Identification or Authentication

NIST800-AC-14 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.

The control as we hold it

AC-14 Permitted Actions Without Identification or Authentication. a. Identify [Assignment: organization-defined user actions] that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and b. Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

SOC 2

What an auditor commonly asks for

General guidance for this control area (domain: AC - Access Control), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control